YoVDO

Reliable Third-Party Library Detection in Android and its Security Applications

Offered By: Association for Computing Machinery (ACM) via YouTube

Tags

ACM CCS (Computer and Communications Security) Courses Android Development Courses Cybersecurity Courses

Course Description

Overview

Explore a comprehensive analysis of third-party library detection in Android applications and its security implications in this conference talk presented at CCS 2016. Delve into the challenges of app security research, library integration, and fragmentation. Learn about the creation of a library database and the process of library profiling, including profile generation and matching techniques. Examine the app and library release intervals, and understand the impact of library version fragmentation on security. Discover methods for detecting vulnerable libraries and gain insights into crypto API (in)security. Enhance your understanding of Android app security and the critical role of third-party library management in maintaining a secure mobile ecosystem.

Syllabus

Intro
Motivation: App Security Research
Library Integration
Status Quo?
Motivation: Library Fragmentation
Library Database
Library Profiling
(2) Profile Generation
(2) Method Hash
Profile Matching
Profile Uniqueness
App / Library Release Interval
Library Study
Library Version Fragmentation
Vulnerable Library Detection
Recap: App Security Research
Crypto API (In)security
Conclusion


Taught by

ACM CCS

Related Courses

Peeling the Onion's User Experience Layer - Examining Naturalistic Use of the Tor Browser
Association for Computing Machinery (ACM) via YouTube
DeepCorr - Strong Flow Correlation Attacks on Tor Using Deep Learning
Association for Computing Machinery (ACM) via YouTube
SandScout - Automatic Detection of Flaws in iOS Sandbox Profiles
Association for Computing Machinery (ACM) via YouTube
Game of Decoys - Optimal Decoy Routing Through Game Theory
Association for Computing Machinery (ACM) via YouTube
PREDATOR - Proactive Recognition and Elimination of Domain Abuse at Time-Of-Registration
Association for Computing Machinery (ACM) via YouTube